Home Data Processing Agreement

Data Processing Agreement

Last updated: 24 September 2026

This Data Processing Agreement ("DPA") forms part of the Agreement between Zentari Networks Ltd ("Zentari", "we", "us") and the Customer, as defined in our Terms of Service. It applies whenever we process personal data on the Customer's behalf in providing the Services, and sets out both parties' obligations under Article 28 of the UK GDPR. It is accepted when the Customer accepts our Terms of Service, including in the Axis platform.

1 Definitions

  • "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other data protection law that applies to the processing.
  • "Customer Personal Data" means personal data we process on the Customer's behalf in providing the Services, as described in Annex 1.
  • "Sub-processor" means a third party we engage to process Customer Personal Data.
  • "Personal Data Breach", "controller", "processor", "data subject" and "processing" have the meanings given in the UK GDPR.
  • Other capitalised terms have the meanings given in our Terms of Service.

2 Roles of the Parties

The Customer is the controller and Zentari is the processor of Customer Personal Data. Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.

Zentari is an independent controller, not a processor, of personal data we use for our own purposes: managing the customer relationship, billing, preventing fraud and network abuse, securing our systems, and meeting our legal and regulatory obligations. That processing is covered by our Privacy Policy, not this DPA.

3 Customer Obligations

  • The Customer is responsible for having a lawful basis for the processing, and for giving any notices to, or obtaining any consents from, data subjects that Data Protection Law requires. This includes the people who use, or are contacted by, the devices in which our SIMs are installed.
  • The Customer's instructions must comply with Data Protection Law.
  • The Customer must not put special category data or criminal offence data into free-text fields in the Services (for example SIM tags or support requests), and must not use the Services to process such data unless we have agreed this in writing.

4 Zentari's Obligations

When processing Customer Personal Data, Zentari will:

  • Instructions — process it only on the Customer's documented instructions, which are the Agreement and the Customer's use and configuration of the Services, unless the law requires otherwise. In that case we will tell the Customer first unless the law prohibits it. We will tell the Customer if we believe an instruction infringes Data Protection Law.
  • Confidentiality — make sure everyone authorised to process it is under a duty of confidentiality.
  • Security — put in place and maintain appropriate technical and organisational measures, including those described in Annex 2.
  • Data subject rights — taking into account the nature of the processing, help the Customer respond to requests from data subjects exercising their rights. If we receive such a request directly, we will pass it to the Customer and not respond ourselves unless the Customer authorises us to.
  • Assistance — provide reasonable help with the Customer's security obligations, data protection impact assessments and consultations with the Information Commissioner's Office, taking into account the nature of the processing and the information available to us.
  • Records — keep a record of our processing activities carried out on the Customer's behalf, as Article 30(2) of the UK GDPR requires.

5 Sub-processors

  • The Customer gives general authorisation for Zentari to engage Sub-processors. The Sub-processors we use at the date of this DPA are listed in Annex 3. Where Annex 3 describes a Sub-processor by category rather than by name, we will give the Customer its name on written request, and the Customer must keep it confidential.
  • We will give at least 30 days' notice of any intended addition or replacement, by updating this page and emailing the Customer's billing or account contact. The Customer may object on reasonable data protection grounds within that period. If we cannot reasonably address the objection, the Customer may terminate the affected Services without penalty.
  • We will put in place a written contract with each Sub-processor that imposes data protection obligations no less protective than those in this DPA. We remain liable to the Customer for our Sub-processors' performance of those obligations.

6 International Transfers

We process Customer Personal Data in the United Kingdom and the European Economic Area. Where we or a Sub-processor transfer it outside the UK, we will make sure the transfer is covered by UK adequacy regulations or by appropriate safeguards under Chapter V of the UK GDPR, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

7 Personal Data Breaches

We will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data. As far as it is available to us, the notice will include:

  • what happened, and the categories and approximate numbers of data subjects and records involved;
  • the likely consequences; and
  • the measures taken or proposed to deal with it, and a contact for more information.

We will update the Customer as more information becomes available, and take reasonable steps to contain the breach and limit its effects. Notifying the Customer does not mean we accept fault or liability.

8 Deletion and Return

When the Services end, the Customer may export its data from the Axis platform, including via the reports and API, before termination takes effect. Within 90 days of the end of the Services, we will delete Customer Personal Data from our live systems.

We may keep Customer Personal Data after that only where the law requires it, or where we need it for billing, accounting, tax, and the establishment, exercise or defence of legal claims. This includes the archived network usage records used to calculate invoices, which we keep for up to 7 years. Anything we keep stays protected by this DPA and is used only for those purposes.

9 Information and Audits

We will make available the information reasonably needed to demonstrate our compliance with this DPA, including written answers to reasonable security questionnaires. Where that isn't enough to demonstrate compliance, or where a regulator requires it, we will allow an audit or inspection. Audits are limited to once in any 12 months unless following a Personal Data Breach, need at least 30 days' written notice, are carried out during business hours by the Customer or an independent auditor bound by confidentiality, and are at the Customer's cost.

10 Liability, Term and Precedence

  • Each party's liability under this DPA is subject to the limitations and exclusions of liability in our Terms of Service, except where Data Protection Law does not allow them.
  • This DPA lasts as long as we process Customer Personal Data on the Customer's behalf.
  • If this DPA conflicts with any other part of the Agreement on the processing of Customer Personal Data, this DPA takes precedence.
  • We may update this DPA to reflect changes in law, our Services or our Sub-processors. Material changes will be notified in the same way as changes to our Terms of Service. We will not reduce the overall level of protection it gives Customer Personal Data.
  • This DPA is governed by the laws of England and Wales.

Annex 1 Details of the Processing

Subject matter & duration Providing IoT/M2M connectivity, eSIM provisioning and the Axis platform under the Agreement, for its duration and the deletion period in section 8.
Nature & purpose Provisioning and managing SIMs and eSIM profiles; carrying data, SMS and voice traffic; collecting, storing and displaying usage records; usage alerts and automated controls (Watchdog); notifications; reporting and API access; customer support.
Categories of data subjects The Customer's authorised users of the Axis platform; people who use, or are associated with, devices containing the Customer's SIMs (for example drivers, employees or members of the public); people who communicate with those devices by call or SMS; and the Customer's contacts who receive alerts or notifications.
Types of personal data
  • SIM and device identifiers: ICCID, IMSI, MSISDN (mobile number), IMEI, SIM PIN/PUK and eSIM activation codes.
  • Network usage records: session start times and durations, data volumes, access point name, IP addresses (including fixed public IPs), mobile country and network codes, and radio technology.
  • Voice and SMS records, including the numbers called or messaged, times and durations. We do not process the content of communications.
  • Account data for Axis users: name, work email, role, and security records (sign-in activity, two-factor settings, acceptance of terms including IP address and browser).
  • Anything the Customer enters in the Services, such as SIM tags, alert recipients, webhook addresses and support requests.
Special category data None intended (see section 3).
Retention Detailed network usage records are kept in the Axis database for 6 months, then remain only in encrypted archive storage for billing and dispute purposes for up to 7 years. Other data is kept for the duration of the Agreement, subject to section 8.

Annex 2 Security Measures

  • Access control — every Axis user has an individual account protected by a password (stored only as a salted Argon2 hash) and mandatory two-factor authentication, with accounts locked after repeated failed sign-in attempts.
  • Least privilege — role-based permissions within each customer workspace (Admin, Manage, Read Only), and access by Zentari staff limited to those who need it to provide and support the Services.
  • Customer separation — each customer's data is logically separated, and every request is restricted to the workspace of the signed-in user or API key.
  • API security — API keys are stored only as hashes, can be replaced by the Customer at any time, and grant access to one workspace only.
  • Encryption in transit — the Axis platform and API are served over HTTPS (TLS), and data is exchanged with our network partner over encrypted connections (HTTPS and SFTP).
  • Monitoring & audit — security-relevant events (such as two-factor changes and resets) are recorded in each workspace's event log and notified to the user by email, and system activity is logged centrally.
  • Data minimisation & retention — detailed usage records are removed from the live database after 6 months (see Annex 1).
  • Incident response — breaches are handled and notified as set out in section 7.

Annex 3 Sub-processors

Sub-processor Purpose Location
Our wholesale connectivity partner and the mobile network operators it uses SIM and eSIM provisioning, network connectivity and usage records United Kingdom (roaming networks where SIMs are used abroad)
Vultr Hosting of the Axis platform and database European Union
Amazon Web Services (AWS) Encrypted archive storage of network usage records European Union (Stockholm, Sweden)
Resend Delivery of platform emails, such as alerts, invitations and security notices United States
Google (Google Workspace) Business email and document storage, including support correspondence with the Customer United Kingdom, European Union and United States
Grafana Labs System logging and monitoring United Kingdom

Payment data is handled by Stripe as an independent controller under its own terms, and is not processed under this DPA.

11 Contact

For questions about this DPA or to exercise any rights under it, please contact:

privacy@zentarinetworks.com

Zentari Networks Ltd, United Kingdom